syncfusion-react-treegrid
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill is a comprehensive documentation set for a legitimate UI component library. All code examples use standard React and Syncfusion patterns.
- [INDIRECT_PROMPT_INJECTION]: The TreeGrid component is designed to ingest and display hierarchical data, creating an attack surface for indirect prompt injection if untrusted data is displayed without caution.
- Ingestion points: Data is bound to the component via the
dataSourceproperty, as seen inSKILL.mdandreferences/data-binding.md. - Boundary markers: The documentation does not specify markers to isolate data content from agent instructions, but it provides security warnings in
references/selection.mdandreferences/state-persistence.mdregarding the use of browser storage. - Capability inventory: The library supports network communication via
DataManagerfor CRUD operations (references/server-integration.md). - Sanitization: Standard UI rendering practices are followed, and the skill encourages secure state management.
Audit Metadata